<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Extortion on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/extortion/</link><description>Recent content in Extortion on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Sun, 22 Jun 2025 19:50:54 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/extortion/index.xml" rel="self" type="application/rss+xml"/><item><title>Klue Hack: Icarus Exploits Salesforce Integrations</title><link>https://zxcloudsecurity.co.uk/posts/klue-hack-icarus-extortion-salesforce-integration-breach/</link><pubDate>Mon, 22 Jun 2026 19:50:54 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/klue-hack-icarus-extortion-salesforce-integration-breach/</guid><description>Extortion group Icarus breaches Klue via Salesforce-linked integrations, hitting hundreds of victims including security firms. What architects must do now.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/cyber-crime/2026/06/22/security-shops-among-the-hundreds-of-klue-hack-victims/5259743">The Register — Security</a></p>
<hr>
<p>A threat actor group called Icarus has breached Klue, a competitive intelligence platform, by exploiting integrations linked to Salesforce, compromising data from hundreds of organisations including security firms. The attack follows a pattern of extortion campaigns targeting SaaS platforms through third-party integration weaknesses. The inclusion of security vendors among the victims raises particular concerns about potential downstream exposure of sensitive client data.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit all Salesforce-connected integrations and OAuth grants immediately — revoke any third-party app permissions that are unused or overly permissive. Review data-sharing agreements with SaaS vendors like Klue to understand what CRM or sales intelligence data they hold on your behalf, and ensure your vendor risk assessments include integration-level attack surface analysis.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/cyber-crime/2026/06/22/security-shops-among-the-hundreds-of-klue-hack-victims/5259743">Security shops among the &lsquo;hundreds&rsquo; of Klue hack victims</a></p>
]]></content:encoded></item></channel></rss>